‘This is not a traditional coding bug’: Experts point to potentially critical security issues at heart of Anthropic’s MCP, expose 150 million downloads and thousands of servers to complete acquisition



  • Ox Researchers Warn Anthropic’s Model Context Protocol Has a Systemic RCE Flaw
  • Vulnerability built into the MCP SDKs in Python, TypeScript, Java, and Rust
  • More than 200,000 cases exposed; Anthropic says the behavior is “expected”

Security researchers Ox have claimed that Anthropic’s Model Context Protocol (MCP) contains a “critical systemic vulnerability” that puts hundreds of thousands of instances at risk of remote code execution (RCE).

Anthropic, on the other hand, reportedly said the system is working as intended.

Leave a Comment

Your email address will not be published. Required fields are marked *